Terminal and SSH
Connect to a Kiste over SSH through kiste.run, without open ports, with pinned host keys and a shared connection.
kiste shell and kiste terminal are the same command. You log in as root.
How the connection works
kiste ssh runs your own OpenSSH client. Its connection travels over HTTPS
to kiste.run and from there to the Kiste's SSH server, so:
- no port is opened on your network or on the Kiste, and nothing listens on the public internet for SSH;
- it works from wherever you can reach kiste.run, also behind strict firewalls and proxies that allow HTTPS;
- the Kiste's host key is pinned: the CLI fetches it over your signed-in connection and SSH refuses anything else, so there is no "unknown host" prompt to click through;
- only your account's device keys are accepted, password login is off.
The first ssh, scp or forward to a Kiste opens one shared connection
that stays for two minutes after its last use. Every further one within that
time skips the tunnel and the key exchange and starts instantly. (OpenSSH for
Windows has no connection sharing, so there each connection is set up anew.)
Run a command
Anything after -- runs as a remote command, with standard input forwarded:
kiste ssh then exits with the remote command's status. Leading options after
-- go to ssh itself:
For scripts, kiste exec is usually better: it runs a program without a shell,
returns its exact output and status, and never needs a terminal. See
Run commands.
Print the ssh command
prints the exact, safely quoted OpenSSH command line without connecting, for
tools that want to run ssh themselves.
Plain ssh, scp and editors
Signing in sets up NAME.kiste as an SSH host on your computer, so plain
ssh review-42.kiste, scp, rsync and editors like VS Code work too. See
SSH configuration and editors.
Limits
- An SSH connection closes after one hour without any traffic in either direction. The CLI sends keep-alives every 15 seconds while a session is open, so an interactive shell stays.
- An account can have 32 SSH connections open at once (L12).
- Stopping, restarting or deleting the Kiste and signing out everywhere close its SSH connections.